1. INTRODUCTION
Please read this Privacy Notice carefully so that you understand how we process your personal data and are aware of your rights regarding data processing.
In the course of its activities, the Szalai Law Firm (hereinafter referred to as the “Data Controller” or “Law Firm”) necessarily processes data; however, it takes great care to protect personal data, comply with mandatory legal provisions, and ensure secure and fair data processing.
The Data Controller informs natural persons about the principles, processes, and safeguards of data processing. The Data Controller recognizes the right of natural persons to have control over their own personal data. At the same time, the Data Controller notes that the right to the protection of personal data is not an absolute right; it must be considered in accordance with the principle of proportionality and balanced against other fundamental rights.
Detailed information regarding each data processing activity can be found in the appendix to this document.
If you need further information regarding the Privacy Policy, please contact the Data Controller using any of the contact details provided.
2. DATA CONTROLLER INFORMATION
3. CONCEPTS AND PRINCIPLES RELATED TO DATA PROCESSING, AS WELL AS RELEVANT LEGISLATION
A. Definitions
The terms used in this information sheet are primarily based on the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as the “Regulation”) and Act LXXVIII of 2017 on the Practice of Law (hereinafter referred to as the “Law on the Practice of Law”), the following provisions have been established as follows:
– Data Subject: any natural person who can be identified, directly or indirectly, based on any of their personal data, and in connection with whom the Data Controller processes personal data. Examples of data subjects include customers and prospective customers.
– Client: A natural or legal person who has entered into a retainer agreement with an attorney, as well as any natural or legal person who uses the services of the law firm, even without having entered into a retainer agreement,
– Personal data: any data or information relating to the Data Subject that can be linked to the Data Subject or that makes the Data Subject identifiable (e.g., name, phone number, online identifier, location data, likeness, voice, etc.) [Article 4(1) of the Regulation] Personal data retains this status during data processing as long as its connection to the Data Subject can be reestablished using the information and technical means available to the Data Controller
– Data protection: the set of principles, rules, procedures, data processing tools, and methods that ensure the lawful processing of personal data and the protection of data subjects
– Data Processor: a natural or legal person or entity that processes data on behalf of and under the authority of the Data Controller. The provisions of this Privacy Notice also apply to the Data Processor
– Third Party: a natural or legal person other than the Data Subject, the Data Controller, the Data Processor, the joint controller, or a person authorized to process data under the direct authority of the Data Processor and the Data Controller. [Article 4(10) of the Regulation]
– Consent of the data subject: a freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her [Article 4 of the Regulation]
– Supervisory authority: National Authority for Data Protection and Freedom of Information (NAIH)
B. Basic Principles
When processing personal data, the data controller acts in accordance with the fundamental principles of data processing (lawfulness, fairness, transparency, purpose limitation, data minimization, proportionality, accuracy, accountability, and privacy by design).
For more information on the principles of data processing, please refer to Article 5 of Regulation (EU) 2016/679 (hereinafter referred to as the “Regulation”) and Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information.
C. Legislation
The Data Controller processes the personal data it handles in all cases in compliance with applicable Hungarian and European laws and data processing principles, and ensures the safeguards necessary for secure data processing. The data processing procedures have been established based on the following laws, in particular, but not exclusively:
– Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the “Regulation”)
– The Fundamental Law of Hungary
– Act V of 2013 on the Civil Code (Ptk.)
– Act LXXVIII of 2017 on the Practice of Law (Law on the Practice of Law)
– Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Infotv.)
– Act C of 2000 on Accounting (Accounting Act)
– Act XX of 1996 on Identification Methods Replacing Personal Identification Numbers and the Use of Identification Codes
– Act LIII of 2017 on the Prevention and Combating of Money Laundering and the Financing of Terrorism (Pmt.)
D. Lawfulness of Data Processing
In our interactions with our clients, colleagues, and partners, we continuously process data in accordance with the applicable legal provisions.
Pursuant to Article 6 of the Regulation, data processing is considered lawful if it is based on one of the legal grounds exhaustively listed in the Regulation. Data processing is considered lawful if any of the following conditions are met:
4. YOUR (CUSTOMER, DATA SUBJECT) RIGHTS
You may contact the Data Controller’s representative directly regarding your requests, questions, complaints, or comments on the Data Controller’s conduct using the contact information provided in Section 2.
You may exercise your rights regarding data processing by submitting a request to the Data Controller. The Data Controller will respond to any inquiry made through any of its contact channels without delay, but no later than within 30 days. You are entitled to exercise your rights as follows: page
A. The Right to Prior Information and the Right of Access (Articles 13–14 of the Regulation)
You have the right to receive confirmation, upon request, as to whether your personal data is being processed. At the data subject’s request, the attorney will provide a copy of the personal data processed by him or her and, at the same time, provide the information specified in Article 15 of the GDPR (such as: the purpose of data processing, the categories of data processed, the categories of recipients to whom the data is disclosed, and the duration of data processing).
B. The Right to Rectification (Article 16 of the Regulation)
At the request of the data subject, the attorney shall correct any inaccurate personal data concerning the data subject that is under the attorney’s control without delay.
C. The Right to Erasure (Article 17 of the Regulation)
Pursuant to Article 17 of the GDPR, the attorney shall erase the data subject’s personal data processed by the attorney without delay, either at the data subject’s request or on his or her own initiative, in the cases specified therein. If the data subject requests the erasure of personal data that the attorney has made public, the attorney shall take all reasonable steps to inform the data controllers processing the data subject’s data that the data subject has requested the erasure of their data.
D. The Right to Restriction of Processing (Article 18 of the Regulation)
At the request of the data subject, the attorney may, in certain cases and subject to the provisions set forth in Article 18 of the GDPR, process the data subject’s personal data on a limited basis. If data processing is restricted at the data subject’s request, the attorney may process such personal data—except for storage—only with the data subject’s consent, or for the purpose of establishing, exercising, or defending legal claims, or to protect the rights of another natural or legal person, or for reasons of substantial public interest.
E. The Right to Data Portability (Article 20 of the Regulation)
In the case of automated data processing based on a contract or consent, the attorney shall, at the data subject’s request, provide the data subject with his or her personal data—which the data subject previously made available to the attorney—in a structured, commonly used, machine-readable format; or, at the data subject’s request, if technically feasible, the lawyer will transmit such data directly to another data controller.
F. The Right to Protest (Article 21 of the Regulation)
If a lawyer processes the data subject’s personal data on the basis of a legitimate interest, the data subject has the right to object at any time to the processing of their personal data for reasons related to their particular situation, in accordance with Article 21 of the GDPR. In such cases, the data controller may no longer process the personal data, except in exceptional cases specified by law.
G. Obligation to provide notice regarding the rectification or erasure of personal data, or the restriction of processing (Article 19 of the Regulation)
H. Notifying the Data Subject of a Data Breach (Article 34 of the Regulation)
I. Right to File a Complaint
You have the right to file a complaint regarding data processing, primarily with the Data Controller and its representative, and secondarily with the supervisory authority of the Member State where you reside, where you work, or where the alleged infringement occurred. The supervisory authority’s contact information is as follows:
National Authority for Data Protection and Freedom of Information
J. Right to Remedies (Articles 78–79 of the Regulation)
You have the right to seek judicial remedy against a binding decision of the supervisory authority concerning you, or if the supervisory authority has failed to address your complaint or has not provided you with information regarding the proceedings related to your complaint within 3 months. The Data Subject may exercise this right to judicial remedy before the competent court. The Data Subject is also entitled to an effective judicial remedy against the Data Controller or the Data Processor if, in the Data Subject’s opinion, their personal data has not been processed in accordance with the provisions of the Regulation. The Data Subject may exercise this right to a judicial remedy before the competent court.
Please contact us electronically whenever possible. Please note that the Data Controller will respond to data protection requests electronically whenever possible, unless the Data Subject expressly requests another method of communication or the Data Controller does not have the Data Subject’s electronic contact information.
Please be advised that if a request for the disclosure of data entails disproportionate additional costs for the Data Controller (e.g., due to the chosen format), the Data Controller is entitled to charge the Data Subject for the costs associated with the disclosure of the data. The Data Controller will inform the Data Subject in advance of any costs that may arise.
Please be advised that a legal representative is authorized to act on behalf of individuals under the age of 18.
5. DATA SECURITY
The Data Controller’s objective is to minimize the processing of personal data in order to reduce data processing risks. The Data Controller processes the personal data it holds in a transparent and verifiable manner to ensure the immediate detection of data breaches.
The Data Controller's Data Security Responsibilities
6. RECIPIENTS OF PERSONAL DATA
Your data may be accessed by attorneys, legal staff (e.g., paralegals, legal assistants), and cooperating or substitute attorneys whom you have approved in the engagement agreement or power of attorney.
Personal data may be transferred to the attorney’s archiving, accounting, and IT service providers for the purpose of data processing. Address information will be transferred to Magyar Posta or the designated courier service when sending mail. Billing information will be shared with the person handling the attorney’s accounting. Personal data may also be transferred to competent authorities, courts, opposing parties, and third parties in accordance with the purpose of the engagement and data processing. If the attorney performs the engagement with the assistance of another attorney or law firm, personal data will be transferred to the cooperating attorney in such cases. Personal data may also be disclosed to other persons assisting in the performance of the legal mandate (e.g., experts) or to other persons engaged in connection with the performance of the mandate, provided that the client has approved their involvement or engagement. If the regional bar association appoints an office manager pursuant to Section 85 of the Attorney Act, the office manager is authorized to represent the attorney and to inspect the documents. Your data may also be disclosed in litigation or administrative proceedings to authorities (e.g., investigative authorities, data protection supervisory authorities, courts), as well as to the opposing party.
In cases prescribed by law, the attorney is required to disclose the personal data specified by law that he or she processes to the institutions, agencies, and organizations designated by law; the attorney shall notify the data subjects of such disclosure, unless prohibited by law.
When transferring data, the attorney acts strictly in accordance with the Act on Attorneys, as well as the ethical rules applicable to attorneys and the provisions of procedural laws. Data processors may process personal data only on the basis of a written contract with the attorney, solely in accordance with the attorney’s instructions, and exclusively in connection with the purposes specified above; they are authorized to process such data no later than the date of termination of the data processing agreement, or for as long as the attorney is authorized or obligated to process the data.
The attorney shall use only data processors who provide adequate safeguards to ensure compliance with the data processing requirements set forth in the GDPR and to implement appropriate technical and organizational measures to protect the personal data of the data subject.
The data controller engages a data processor to ensure the operation of the website (web hosting services, data entry on the website) and enters into a data processing agreement with that party.
Data Processor Information:
Name: Gergő Bercsényi (ret.)
Headquarters: 9029 Győr, Csutora St. 3/a
Contact: mepps@mepps.hu
Data processed by the data processor: data uploaded to the website; data provided to the data controller via the website (by completing the data request questionnaire)
As a general rule, the Data Controller does not transfer data to third countries (i.e., countries outside the European Union). If such a data transfer occurs on an ad hoc basis, the Data Controller will transfer personal data to a third country that, according to a Commission adequacy decision, ensures an adequate level of protection; or, if no adequacy decision is available, the Data Controller will transfer personal data to a third country only if the conditions set forth in Articles 46 or 49 of the GDPR are met.
7. DATA PROTECTION INCIDENT
A data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data that is transmitted, stored, or otherwise processed [Article 4 of the Regulation].
If you become aware of a data breach or a potential data breach in connection with any of our data processing activities, please notify the Attorney immediately using the contact information provided in this notice.
In the event of a data breach, we will report the incident to the authority immediately—but no later than 72 hours after it occurs—unless an assessment determines that it poses no risk to the rights and freedoms of natural persons. If the incident is likely to pose a high risk to the rights and freedoms of natural persons, we will notify the data subject immediately.
We investigate every data breach and take the appropriate measures to ensure that a similar incident does not occur again in the future.
We maintain a record of data protection incidents, which includes all relevant details of each incident.
Győr, November 1, 2025
DATA PROCESSING ACTIVITIES
A. Data Processing in Connection with a Legal Retainer and Attorney Identification
B. Case Registry
C. Case records for matters requiring mandatory legal representation
D. Processing of contact information for clients and contractual partners
E. Data processing related to the countersigning of documents serving as the basis for entry into the official registry
F. Customer due diligence pursuant to the Pmt.
G. Data of Other Data Subjects
H. Record of attorney escrow accounts
I. Data Transfer to Cooperating Law Firms, Agents, and Deputies
J. Data processing related to requests from data subjects
K. Data processing related to data protection incidents
L. Data processing by the website, cookies
A. Data Processing in the Context of a Legal Retainer and Attorney Identification
A lawyer processes personal data in the course of providing legal services pursuant to Section 27 of the Act on Lawyers.
The scope of the data processed may be determined by law (e.g., mandatory elements of a contract) or, in specific administrative or litigation proceedings, by a request from the relevant authority.
Section 32(1) of the Act: With the exception of engagements for legal advice, prior to the conclusion of the engagement agreement and before the countersigning of the contract between the attorney-at-law, his or her employer, and a third party, the Bar Association legal advisor (hereinafter collectively referred to as “attorney” for the purposes of this subsection) shall verify the identity of the client, the Bar Association’s legal advisor shall verify the identity of the client, the person contracting with the attorney’s employer, and any person acting on their behalf.
(2) A lawyer shall verify the identity of a natural person whom he or she does not know, or whose identity is in doubt, by examining a document suitable for identification purposes.
In order to verify that a natural person’s information matches the records on file and that the documents presented by the person are valid, the attorney may request data from the personal data and address registry, the driver’s license registry, and the travel document registry. The attorney shall submit the data request if any doubts arise regarding the validity or authenticity of the data or documents.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
|
customer's name and address |
Entering into a contract for services |
Performance of a contract for legal services, pursuant to Article 6(1)(b) of the Regulation |
|
|
billing |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Section 169 of the VAT Act, Sections 167 and 169 of the Accounting Act |
||
|
customer's phone number, name |
maintaining contact |
Performance of a contract for legal services, pursuant to Article 6(1)(b) of the Regulation |
|
|
Customer data pursuant to Section 32(3) of the Act on the Treatment of Personal Data in cases of doubt |
Verification of data collected during customer identification |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Section 32(2) and (3) of the Act |
|
|
Additional information required for the assignment, regarding the client |
Representing the client's interests and providing the service |
Pursuant to Article 6(1)(b) of the Regulation, the performance of a contract for legal services and the obligation to cooperate arising from the contract |
|
Duration of data processing: 8 years from the termination of the contract; in the event of a legal dispute, if the later date applies, 5 years following the resolution of the dispute.
B. Case Registry
Pursuant to Section 53 of the Act on Attorneys, an attorney maintains a record to ensure that compliance with the rules governing the practice of law can be verified and to protect the rights of clients in the event that the attorney’s license to practice is revoked.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
Data pursuant to Section 53(2) of the Act |
Compliance with the legal requirement to maintain a case registry |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Section 53(1) and (2) of the Act |
Duration of data processing: 5 years following the termination of the mandate; 10 years following the countersigning of a document, if applicable; and 10 years from the date of registration of a right pertaining to real property in an official registry, in cases involving such registration.
Section 53(2) of the Act. The records kept on cases shall contain the following information:
a) the case identification number assigned by the attorney,
b) the client’s name,
c) the subject matter of the case,
d) the date the retainer agreement was entered into, and
e) the case number of any court proceedings related to the matter, or the file number of any other proceedings.
(3) The attorney shall retain the data specified in paragraph (2) for five years following the termination of the retainer; in the case of the countersigning of a document, for ten years following the countersigning of the document; and in matters concerning the registration of a right pertaining to real property in a public registry, for ten years from the date of such registration.
C. Case Registry for Cases Requiring Mandatory Legal Representation
Pursuant to Section 33(1) of the Act on Lawyers, a lawyer shall maintain a record of cases in which legal representation is mandatory.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
Data pursuant to Section 33(2) of the Act |
Compliance with the legal requirement to maintain a case registry |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Section 33(1) and (2) of the Act |
Section 33(1) of the Act: In cases where legal representation is mandatory, an attorney shall maintain a record of natural persons identified by means of a document suitable for at least identification purposes, as well as of legal entities and other organizations, in order to promote the security of legal transactions and to enforce the limitations on the practice of law.
(2) The registry of identified natural persons contains the following information:
a) personal identification data,
b) address,
c) citizenship, statelessness, refugee status, immigrant status, settled resident status, or EEA citizen status,
d) the type and number of the identification document used for identification,
e) the identifier of the response received in connection with the data request specified in Section 32(3),
f) the case identifier for cases in which the identification of a natural person is mandatory,
g) the data specified in the Act on the Prevention and Combating of Money Laundering and Terrorist Financing.
(3) If, based on the review conducted pursuant to Section 32(8), the attorney determines that there has been a change in the information specified in paragraph (2)(a) through (d) and (g), the attorney shall record the changed information, indicating the date of the review, in such a way that the previously recorded information remains accessible.
(7) The attorney shall retain the data specified in paragraphs (2) and (4) for the period specified in the Act on the Prevention and Combating of Money Laundering and Terrorist Financing.
Duration of data processing: 8 years from the termination of the contract.
D. Processing of Contact Information for Customers and Contractual Partners
In the course of their relationships with contractual partners and clients, attorneys process the personal data of their partners’ contacts and representatives. Due to the nature of the data, it may be necessary to process personal data (name, email address, phone number). The data controller draws the attention of its contractual partners and clients to the fact that they should inform the contact persons and representatives they have designated about the processing of their data.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
Name, contact information (phone number, email address), and position of the contact person or representative |
Ensuring effective collaboration with contractual partners and clients; maintaining records of data necessary for business communication |
Pursuant to Article 6(1)(f) of the Regulation, the Data Controller has a legitimate interest in ensuring the continuity and smooth operation of its business relationships |
Data processing continues until the termination of the contractual relationship or, in the case of ongoing cooperation, until June 30 of the calendar year following the end of such cooperation (the document destruction deadline). If the data is included in the service agreement, we will store the data—in accordance with the rules governing the service agreement—for 8 years from the termination of the agreement.
E. Data Processing Related to the Counter-Signing of Documents Serving as the Basis for Entry in the Official Register
A lawyer is required to identify his or her clients when countersigning a document that serves as the basis for entry in a public registry. The method of identification and the scope of the data processed are specified in Section 32 of the Act on Lawyers.
Section 32 of the Act (7) Prior to countersigning the document serving as the basis for entry in the official registry, the attorney shall—for the purpose of verifying identity and the validity of the document—identify the persons and organizations making the legal declaration, as well as the persons acting on their behalf, in accordance with paragraphs (2) through (4) and (6).
(3) In order to verify that a natural person’s information matches the recorded data and that the documents presented by the person are valid, the attorney may access the personal data and address registry, the driver’s license registry, the travel document registry, and the central immigration registry:
a) natural person identification data,
b) citizenship, statelessness, refugee status, immigrant status, permanent resident status, or EEA citizen status,
c) address,
d) photograph,
e) signature,
f) facts as defined in Section 18(5) of Act LXVI of 1992 on the Registration of Citizens’ Personal Data and Addresses,
g) data specified in Section 24(1)(f) of Act XII of 1998 on Travel Abroad and the document’s period of validity,
h) data specified in Section 8(1)(b)(ba)-(bb) of Act LXXXIV of 1999 on the Road Traffic Registry,
i) Section 76(d) and Section 80(1)(b) and (c) of Act I of 2007 on the Entry and Residence of Persons Enjoying the Right to Free Movement and Residence, as well as data pursuant to Section 95(1)(g), Section 96(1)(g), and Section 100(1)(b) and (c) of Act II of 2007 on the Entry and Residence of Third-Country Nationals.
(6) If an authorized representative acts on behalf of a natural person client, the attorney may omit the separate identification of the client, provided that the power of attorney—which contains the client’s identifying information—has been countersigned by the attorney, drawn up by a notary public, the principal’s signature has been certified by a notary public, or the power of attorney has been certified or legalized by the competent Hungarian diplomatic or consular mission at the place of signature, or it has been affixed with an Apostille.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
Customer data specified in Section 32(3) of the Act on Customer Protection |
verifying a customer's identity |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Section 32(7) of the Act |
Section 53 of the Act (5) In the case of the countersigning of a document, the attorney shall retain the document countersigned by him or her, as well as any other documents arising from the matter involving the countersigning of the document, for a period of ten years from the date of countersigning, unless a longer retention period is prescribed by law or the parties have agreed to a longer retention period.
Duration of data processing: 10 years from the termination of the contract.
F. Customer Due Diligence Under the Pmt.
Pursuant to Section 6(1) of the Pmt., an attorney is required to conduct client due diligence in the following cases:
a) upon establishing a business relationship;
b) upon the execution of a transaction order amounting to four million five hundred thousand forints or more;
c) in the case of a merchant, upon the execution of a transaction order in cash in an amount equal to or exceeding three million forints;
d) upon the execution of a transaction order exceeding three hundred thousand forints that qualifies as a funds transfer as defined in Article 3, paragraph 9 of the Decree;
e) in the case of an organizer of bets not classified as remote gambling, when paying out winnings of six hundred thousand forints or more for bets organized via non-telecommunications devices and systems that do not constitute remote gambling, in the case of bets not classified as remote gambling organized via telecommunications devices and systems, upon the payment of a player’s balance amounting to or exceeding six hundred thousand forints;
f) if data, facts, or circumstances indicating money laundering or terrorist financing arise, provided that due diligence has not yet been conducted in accordance with points a) through e) or i);
g) if doubts arise regarding the authenticity or accuracy of previously recorded customer identification data;
h) if a change in customer identification data is recorded and, based on a risk-sensitive approach, it is necessary to repeat the customer due diligence;
i) in the case of a currency exchange transaction amounting to three hundred thousand forints or more.
§ (1) In the cases specified in § 6(1)(a) and (e)-(h), the service provider is required to identify the customer, the customer’s authorized representative, the person authorized to act on the customer’s behalf, and the representative acting on behalf of the service provider, and to verify their identity.
(2) During the identification process, the service provider is required to record the following information:
a) a natural person
aa) first and last name,
ab) birth first and last name,
ac) their citizenship,
ad) place and date of birth,
ae) his or her mother’s maiden name,
af) his or her address, or, in the absence thereof, his or her place of residence,
ag) the type and number of his or her identification document;
b) a legal entity or an organization without legal personality
ba) its name, abbreviated name, page
bb) the address of its registered office or, in the case of a foreign-based enterprise—if it has one—the address of its Hungarian branch,
bc) its main activity,
bd) the names and titles of those authorized to represent it,
be) – if applicable – the details of its authorized agent for service of process as specified in subparagraphs (aa) and (af) of paragraph (a),
bf) in the case of a legal entity listed in the commercial register, its company registration number; in the case of other legal entities, the number of the decision regarding its establishment (registration, incorporation) or its registration number,
bg) its tax identification number.
(3) In order to verify a person’s identity, the service provider is required to request the presentation of the following documents or is authorized to retrieve data from an official registry:
a) a natural person
aa) in the case of a Hungarian citizen, an official identification document suitable for verifying identity and an official document verifying their address, the latter if their place of residence or stay is located in Hungary,
ab) in the case of a foreign national, a travel document or identity card, provided that it entitles the holder to stay in Hungary; a document certifying the right of residence or a document authorizing residence; and an official document certifying their address in Hungary, provided that their place of residence or place of stay is in Hungary;
b) in the case of a legal entity or an organization without legal personality, the person authorized to act on its behalf or under its authority must, in addition to presenting the document specified in point a), present a document—not older than thirty days—certifying that
(ba) the company has been registered by the commercial court or has submitted an application for registration; in the case of a sole proprietor, the commencement of sole proprietorship activities has been reported or the sole proprietor has been registered;
bb) in the case of a domestic legal entity not covered by subparagraph ba) of paragraph b), if its formation requires registration with an administrative authority or a court, such registration has been completed;
bc) in the case of a foreign legal entity or an organization without legal personality, registration or enrollment in accordance with the laws of its home country has been completed;
(c) the founding document of a legal entity or an organization without legal personality, prior to the submission of an application for registration with a court or administrative authority.
(3a) The verification of the data specified in subparagraphs (ab) through (ac) and (ae) of paragraph (2)(a) may be omitted if the document presented for the purpose of verifying identity does not contain such data.
(3b) In the case specified in paragraph (3a), the service provider is required to record information indicating that the data specified in paragraph (2)(a)(ab) through (ac) and (ae) were recorded without an audit.
(5) In order to verify the identity of the customer, the service provider is required to verify the validity of the identification document presented pursuant to paragraph (3) and, in doing so, must ensure the authenticity of the document.
(6) When verifying identity, the service provider is required to verify, in the case of an authorized representative, the validity of the power of attorney, the authority of the person entitled to dispose of the account, and the representative’s authority to act on behalf of that person.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
the customer's information as set forth in Section 7(2) of the Pmt. |
Conducting customer due diligence and ensuring compliance with legal requirements |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Pmt. Section 6(1), Section 7(1) and (2) |
Duration of data processing: 8 years from the termination of the contract.
Section 57(1) of the Pmt. The service provider shall, in the records it maintains, retain data that does not qualify as personal data—including data obtained during electronic identification— as well as all other data generated in connection with the business relationship—in the records it maintains—for a period of eight years from the termination of the business relationship or the fulfillment of the transaction order.
(2) The service provider shall, in the records it maintains, retain the documents or copies thereof that come into its possession in the course of fulfilling the obligations set forth in this Act and in legislation authorized by it—including documents obtained during the electronic identification process— as well as documents evidencing the fulfillment of the reporting obligation and the provision of data pursuant to Section 42, documents evidencing the suspension of the transaction’s execution pursuant to Sections 34 and 35, or copies thereof, as well as all other documents arising in connection with the business relationship, or copies thereof, for a period of eight years from the termination of the business relationship or from the execution of the transaction order.
G. Information on other affected parties
Data subjects: other participants in the proceedings, opposing party, legal representative of the opposing party, third parties not participating in the proceedings (e.g., data regarding a client’s family members)
If the personal data originates from the client, the client is required to declare that he or she is authorized to process the data and transfer it to the Attorney, and that he or she has an appropriate legal basis for the data transfer, thereby fulfilling the obligation to provide information. Pursuant to Article 14(5)(a) of the Regulation—and in light of the client’s fulfillment of the obligation to provide information—the attorney will not provide separate notice to the data subject.
A lawyer is not subject to a duty to disclose information if the personal data being processed is covered by attorney-client privilege (Article 14(5) of the GDPR)
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
Additional information required for the assignment, where the data subject is an external party |
Representing the client's interests and providing the service |
Pursuant to Article 6(1)(f) of the Regulation, the legitimate interest of the Data Controller and the client is to ensure successful cooperation regarding the subject matter of the engagement and the effective performance of legal services. |
Duration of data retention: The duration of data retention for each type of case is determined by the legal obligations applicable to attorneys. Attorneys retain data only for the period specified by law.
Section 46(5) of the Act: Unless the parties have agreed on a longer retention period, an attorney shall retain the electronic document for ten years from the date a copy was made.
(6) A lawyer shall retain a paper document that has been converted into electronic form and countersigned by the lawyer for a period of five years from the date of conversion, unless the parties have agreed to a longer retention period.
H. Lawyer Escrow Registry
In accordance with Section 7.4 of Regulation No. 7/2018 (March 26) of the Hungarian Bar Association on attorney escrow accounts and escrow records, the attorney maintains a record of the attorney escrow account.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
the subject of the deposit |
Compliance with the legal requirement to maintain a depository register |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Section 158 of the Act Section 7.4 of MÜK Regulation No. 7/2018 (March 26) on the Custody of Documents by Attorneys and the Maintenance of a Register of Deposits |
Duration of data processing: 10 years from the termination of the custody agreement, in accordance with the referenced MÜK regulations.
I. Data Transfer to Partner Law Firms, Agents, and Deputies
It is in the legitimate interest of the attorney and the client (including cases where the client is not the data subject, in particular: when the client is a legal entity or other organization, or with respect to the data of persons other than the client) to seek the assistance of other law firms specializing in the relevant field, individual attorneys, European Community lawyers, or other advisors. Clients will be informed of the identities and, if necessary, the professional qualifications of such additional law firms, individual attorneys, European Union lawyers, and consultants—taking into account the specific nature of the communication—and the Attorney will take the clients’ requests into account to the greatest extent possible when selecting these individuals.
The scope of the data processed during data transfer depends on the nature of the specific assignment.
The legal basis for the data transfer, pursuant to Article 6(1)(f) of the Regulation, is the legitimate interest of the Data Controller and the client in the successful fulfillment of the assignment and the involvement of necessary experts.
J. Data Processing Related to Data Subject Requests
A lawyer is required to maintain records of data protection requests and of the data processed in connection with the exercise of the data subject’s rights.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
Personal data related to data protection requests: in the case of natural persons, legal entities, or other organizations, the contact information of the designated contact persons necessary for communication (including, in particular: name, address, email address), the content of the request, and the request itself Steps taken in connection with the matter and documents prepared in connection with the inquiry |
Compliance with the legal obligation to maintain a record of applications, in accordance with the principle of accountability |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Enabling data subjects to exercise their rights as set forth in Articles 15–22 of the Regulation, and documenting other actions taken in connection with the request |
Duration of data processing: in the absence of different guidelines from the data protection authority, 5 years from the date of the request, given that it is realistic to expect that any data protection claims may be asserted before the data protection authority or a court within this period (Civil Code § 6:22 (1)—unless otherwise provided by the Civil Code, claims become time-barred after 5 years)
K. Data Processing Related to Data Breaches
Lawyers are required to maintain a record of data protection incidents. This record enables the data protection authority to verify compliance with the requirements of the Regulation.
|
Scope of Processed Data |
Purpose of Data Processing |
Legal Basis for Data Processing |
|
the facts surrounding the data protection incident at |
Compliance with the legal requirement to maintain a record of incidents, in accordance with the principle of accountability |
Legal obligation applicable to the Data Controller pursuant to Article 6(1)(c) of the Regulation Article 33(5) of the Regulation |
Duration of data processing: in the absence of different guidelines from the data protection authority, 5 years from the date of becoming aware of the data breach, given that it is realistic to expect that any data protection claims may be asserted before the data protection authority or a court within this period (Civil Code § 6:22 (1)—unless otherwise provided by the Civil Code, claims become time-barred after 5 years)
L. Data Processing by the Website, Cookies
Our website uses cookies to enhance the user experience and ensure the website functions properly. A cookie is a piece of data that the website sends to the user’s browser, allowing the browser to store certain information so that the website can restore the original settings when the user visits again. When visiting the website, the user is informed about the cookies used on the site. The user uses the website with this information in mind.
The purpose of cookies is to enhance the user experience while using the website and to provide the Data Controller with information to monitor the site’s operation.
The cookies used cannot be used to identify the Data Subject. Refusing to consent to the use of cookies does not result in any disadvantage to the Data Subject.
You can delete cookies from your own computer or block their use in your browser. These options vary depending on the browser, but are typically found under the “Settings” or “Privacy” menu. The Data Controller provides a “Cookie Notice” when you access the website.